Vulnerability in Oracle E-Business Suite Personalization Component
CVE-2025-50090

5.4MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 July 2025

What is CVE-2025-50090?

A vulnerability exists in the Oracle Applications Framework component of Oracle E-Business Suite that allows a low privileged attacker with network access via HTTP to compromise sensitive data. Exploitation requires human interaction, with potential impacts on additional products beyond the framework. The vulnerability enables unauthorized updates, insertions, or deletions within accessible data, as well as unauthorized read access to some data sets. This vulnerability highlights the need for stringent security measures and timely patching to protect against potential exploits.

Affected Version(s)

Oracle Applications Framework 12.2.3 <= 12.2.14

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-50090 : Vulnerability in Oracle E-Business Suite Personalization Component